Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
14,991 exploits
GitHub PoC865
KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
CVE-2026-43499HIGH17 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC1
MiaPatsune/cve-2026-43499
CVE-2026-43499HIGH17 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC6
sorrow404Null/CVE-2026-43499-RMX5200
CVE-2026-43499HIGH17 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
Pentest completo sobre Metasploitable: recon con nmap, explotación con Metasploit (CVE-2007-2447), extracción y cracking de credenciales, persistencia SSH
CVE-2007-244717 Jul 2026
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISK
open
GitHub PoC
Reproducer for CVE-2026-48203: Apache Camel camel-solr SolrParam./SolrField. header injection enabling Solr document-field injection and SSRF via the shards parameter (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-48203CRITICAL17 Jul 2026
Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields
48RISK
open
GitHub PoC
Python port of the CVE-2023-23752 exploit — Joomla! < 4.2.8 unauthenticated information disclosure (user list + DB credentials leak)
CVE-2023-23752MEDIUMunder attack17 Jul 2026
[20230201] - Core - Improper access check in webservice endpoints
100RISK
open
GitHub PoC4
HIKRAVEN - Advanced Hikvision Security Assessment Platform for professional penetration testing. Detects 12+ CVEs including CVE-2021-36260 (CRITICAL), tests default credentials, performs network discovery, and generates professional security reports. For authorized security testing only! 🛡️🔒
CVE-2021-36260CRITICALunder attack17 Jul 2026
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,
100RISK
open
GitHub PoC1
Reproducer for CVE-2026-48205: Apache Camel camel-dns dns.* header injection redirecting DNS queries to an attacker-controlled resolver (SSRF via DNS) and enabling internal-hostname reconnaissance (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-48205CRITICAL17 Jul 2026
Apache Camel DNS: The dns.* and term Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour
48RISK
open
GitHub PoC45
CVE-2026-50416: Windows 11 KASLR bypass
CVE-2026-50416LOW17 Jul 2026
Win32k Information Disclosure Vulnerability
28RISK
open
GitHub PoC
Academic proof-of-concept demonstrating CVE-2026-15583 for authorized security research.
CVE-2026-15583HIGH17 Jul 2026
SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header
41RISK
open
GitHub PoC
Reproducer for CVE-2026-48204: Apache Camel camel-mongodb-gridfs gridfs.* header injection overriding the GridFS operation (enumerate/read/delete files) from an unauthenticated HTTP request (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-48204CRITICAL17 Jul 2026
Apache Camel: Camel-MongoDB-GridFS: The gridfs.* control headers used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to switch the GridFS operation - including destructive file deletion - in the default configuration
48RISK
open
GitHub PoC
CVE-2026-43499 exploit with OnePlus Ace3 support
CVE-2026-43499HIGH16 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
CVE-2026-43499 exploit reproduction on jinghu (Xiaomi Pad 7 Ultra)
CVE-2026-43499HIGH16 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
Reproducer for CVE-2026-46592: Apache Camel camel-cxf operationName header injection redirecting the invoked SOAP operation (confused deputy) from a read to a destructive one (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-46592HIGH16 Jul 2026
Apache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation
41RISK
open
GitHub PoC6
Proof of concept for CVE-2026-54992, an MSMQ remote-read integer overflow
CVE-2026-54992HIGH16 Jul 2026
Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability
41RISK
open
GitHub PoC
sadb98523-eng/CVE-2026-13001
CVE-2026-13001CRITICAL16 Jul 2026
Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
63RISK
open
GitHub PoC2
syxlox/CVE-2026-50369
CVE-2026-50369HIGH16 Jul 2026
Windows Remote Desktop Services Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC1
Super Forms Unauthenticated File Upload RCE | CVSS 9.8
CVE-2026-14894CRITICAL16 Jul 2026
Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
63RISK
open
GitHub PoC
Reproducer for CVE-2026-46726: Apache Camel camel-vertx-websocket unfiltered inbound header injection enabling SSRF and secret disclosure via property-placeholder resolution (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-46726HIGH16 Jul 2026
Apache Camel Vertx Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers
41RISK
open
GitHub PoC2
PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes exploit, validator, payload generator, and Metasploit module. For educational and authorized pentesting only.
CVE-2026-58457CRITICAL16 Jul 2026
Shenzhen Aitemi M300 MT02 Unauthenticated OS Command Injection via protocol.csp
48RISK
open
GitHub PoC
uname1able/CVE-2025-21333
CVE-2025-21333HIGHunder attack16 Jul 2026
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
71RISK
open
GitHub PoC
bibotai/secveri-cve-2026-50011-positive
CVE-2026-50011HIGH16 Jul 2026
Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array length
41RISK
open
GitHub PoC
bibotai/secveri-cve-2026-50011-negative
CVE-2026-50011HIGH16 Jul 2026
Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array length
41RISK
open
GitHub PoC52
Local privilege-escalation proof of concept for the Windows WalletService vulnerability fixed in July 2026.
CVE-2026-49176HIGH16 Jul 2026
Windows WalletService Elevation of Privilege Vulnerability
41RISK
open
GitHub PoC
Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).
CVE-2021-44228CRITICALunder attackransomware16 Jul 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RISK
open
GitHub PoC3
🔐 CVE-2026-57821 - Apache Fineract SQL Injection Toolkit 📚 Two Python scripts for authorized security testing: verifier.py (safe detection, no extraction) and exploit.py (deep analysis). Supports 11 DB types. Perfect for understanding SQL injection vulnerabilities. Only legal tests ⚠️ for educational & research purposes only.
CVE-2026-57821HIGH16 Jul 2026
Apache Fineract: Office list: SQL Injection via Subquery in orderBy
41RISK
open
GitHub PoC6
CVE-2026-43499 GhostLock exploit for Redmi K70 Ultra (rothko) - data-only physmap overwrite
CVE-2026-43499HIGH16 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
CVE-2026-43499 exploit with OnePlus Ace3 support
CVE-2026-43499HIGH16 Jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RISK
open
GitHub PoC
Sana-404/CVE-2026-8838-Mitigation-and-Detection
CVE-2026-8838CRITICAL16 Jul 2026
Remote Code Execution via eval() Injection in amazon-redshift-python-driver
48RISK
open
GitHub PoC
Sana-404/CVE-2026-8388-Mitigation-and-Detection
CVE-2026-8388MEDIUM16 Jul 2026
Incorrect boundary conditions in the JavaScript Engine: JIT component
33RISK
open

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.